An issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_invalid_imports can allow Cheetah code to import Python modules via the "#from MODULE import" substring. (Only lines beginning with #import are blocked.)
2022-02-19T00:15:17.013
2024-11-21T06:31:54.773
Modified
CVSSv3.1: 7.8 (HIGH)
AV:L/AC:L/Au:N/C:P/I:P/A:P
3.9
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | cobbler_project | cobbler | < 3.3.1 | Yes |
Application | opensuse | factory | - | Yes |
Operating System | opensuse | backports | sle-15 | Yes |
Operating System | opensuse | backports | sle-15 | Yes |
Operating System | suse | linux_enterprise_server | 11 | Yes |
Operating System | suse | linux_enterprise_server | 12 | Yes |
Operating System | suse | linux_enterprise_server | 15 | Yes |
Operating System | suse | linux_enterprise_server | 15 | Yes |
Operating System | fedoraproject | fedora | 34 | Yes |
Operating System | fedoraproject | fedora | 35 | Yes |
Operating System | fedoraproject | fedora | 36 | Yes |